List View

Apr, 2025

Ransomware Attack Against Kintetsu World Express (KWE)

In April 2025, Kintetsu World Express confirmed that a ransomware attack caused a significant server failure, disrupting parts of its operations. An Emergency Response Headquarters was established, and forensic investigations are underway in collaboration with external experts and Japanese law enforcement. While most systems remain operational, recovery of the affected components is ongoing. The company is taking precautionary steps to assess and strengthen its cybersecurity and will notify customers if their data is found to be impacted. KWE continues to provide services with minimal disruption and has apologized for the inconvenience caused.

Mar, 2025

GPS Jamming Affects Bangladeshi Bulker

In December 2024, the Bangladeshi bulk carrier Meghna Princess ran aground near Russia's Ust-Luga port, reportedly due to GPS jamming. The vessel suffered hull damage, and the crew faced weeks without aid, resorting to melting snow for water. After ITF intervention, salvage operations began, and by March 6, 2025, the ship was refloated and escorted to safety. This incident underscores the challenges posed by GPS jamming in the Baltic Sea.

Mar, 2025

Reported GPS Jamming in Strait of Hormuz

On March 10, 2025, multiple vessels transiting the Strait of Hormuz reported significant GPS jamming incidents, disrupting electronic navigation systems for several hours. The UK's maritime security agency, UK Maritime Trade Operations (UKMTO), acknowledged these reports, and in its Advisory UKMTO #6, recommended to shipmasters to rely on traditional navigation methods during such disruptions.

Mar, 2025

Lab Dookhtegan Disrupts Communications of Iranian Oil Tankers

The cybersecurity company Cydome reported that the anti-Iranian government hacktivist group "Lab Dookhtegan" claimed to have disrupted communications on over 100 oil tankers associated with Iranian government-linked companies. The group announced via their Telegram channel that they successfully interrupted both internal and external communications of these vessels, effectively isolating them at sea. While Lab Dookhtegan did not disclose the specific methods used, it is believed they exploited vulnerabilities in the ships' satellite communication systems, such as VSAT terminals. These systems are known to be susceptible to cyberattacks, especially when default passwords remain unchanged. From those systems they can take complete control over all communications of the vessel and even spread out to the IT and OT systems.

Mar, 2025

Indian APT Intensifies Attacks Against Maritime Facilities

As a continuation of their 2024 activities, the Sidewinder APT, has intensified its cyber espionage operations by targeting maritime facilities across multiple regions. Notably, a South Asian port authority received phishing emails with counterfeit maritime safety protocols, resulting in unauthorized network access and potential data compromise. Their attack methodology includes spear-phishing campaigns with the subsequent exploitation of vulnerabilities such as CVE-2017-0199 and CVE-2017-11882, to execute malicious code upon opening of decoy documents. ​Then malicious documents were crafted to exploit vulnerabilities in Microsoft Office’s Equation Editor, facilitating the deployment of backdoor tools.

Mar, 2025

Chinese Fleet Systematic AIS Disabling for Illegal Fishing

Over 2020-2025 and beyond, Chinese fishing vessels (500+ documented in Argentine waters alone) have systematically employed a coordinated cyber-enabled tactic: deliberate AIS (Automatic Identification System) disabling to conduct illegal, unreported, unregulated (IUU) fishing in other nations' exclusive economic zones. Vessels transit with AIS transponders active until approaching a target EEZ boundary, then power down the AIS to "go dark," rendering them invisible to maritime domain awareness systems. During periods of AIS darkness (often 24+ hours), Chinese vessels conduct illegal fishing operations using satellite surveillance evasion and flag-hopping tactics. Upon exiting the EEZ, AIS is reactivated, leaving only data gaps detectable by satellite imagery analysis. This pattern represents a profound vulnerability in maritime governance: while AIS provides transparency for 94% of fishing activity, the deliberate 6% gap conceals massive environmental damage (species depletion, ecosystem destruction, ghost fishing), economic loss (West Africa alone loses $2.3 billion annually), and human rights abuses (forced labor, trafficking). The Chinese government subsidizes these fleets (up to 50% of costs) and operates them partly through People's Armed Forces Maritime Militia (PAFMM) vessels disguised as commercial fishing. Global Fishing Watch satellite surveillance has documented 55,000+ AIS disabling events (2017-2019 alone), identifying hotspots in Argentina Atlantic, Indian Ocean tuna regions, Somalia, West Africa, and Northwest Pacific. This incident class represents a critical maritime cyber vulnerability—deliberate digital system manipulation enabling international maritime crime and environmental catastrophe.

Feb, 2025

Port of Ostend (Belgium) hit by a hacking incident on the Ensor port community system

In February 2025, the Belgian Port of Ostend reported a hacking incident against its "Ensor" port community system, which stores data on ship arrivals, departures and crew lists. The port stated that the affected system does not handle critical data and that other operational systems were not disrupted. Internal IT staff, external cyber experts and the Centre for Cybersecurity Belgium were engaged to investigate and restore the system, and a complaint was filed with the federal police.

Jan, 2025

AIS Spoofing from Chinese-owned ship Suspected of Damaging a Subsea Cable off the North Coast of Taiwan

A Chinese-flagged vessel, Fu Yang 6, suspected of involvement in recent undersea cable sabotage near Taiwan, may have been using two AIS transponders simultaneously. This unusual configuration could allow the ship to obscure its true location and activities. The ship has been linked to damage caused to undersea cables connecting Taiwan to its outlying islands, a critical infrastructure for communication. Authorities speculate that the dual AIS setup might be a deliberate tactic for deception, aligning with suspicions of Chinese interference in regional telecommunications and security.

Jan, 2025

DDoS Attacks Against Port of Trieste

The Trieste Free Port, a key NATO logistics hub, experienced a significant cyberattack believed to be orchestrated by the pro-Russian hacker group Noname057(16). The attack disrupted port operations and raised concerns about its potential impact on NATO’s supply chain, given the port's strategic importance in supporting military logistics. Trieste authorities reported that the attack, likely politically motivated, targeted IT systems critical to port operations. This aligns with broader trends of cyberattacks on critical infrastructure in countries perceived as supporting Ukraine.

Jan, 2025

Teenager Hacks Ship Routes in the Mediterranean

In January 2025, a teenage hacker managed to infiltrate a system of the Ministry of Education and Merit to change their grades as well as, a system responsible for maritime route management in the Mediterranean Sea, allowing them to manipulate ship positioning data. By exploiting vulnerabilities, they ware able to divert vessels and interfere with navigation, causing disruptions to maritime traffic. However, their actions appeared to be driven by curiosity and a desire to test their skills rather than malicious intent. Authorities detected the breach and launched an investigation, ultimately identifying and arresting the teenager.